|
1 | | -import { describe, it, expect, vi, beforeEach } from 'vitest'; |
| 1 | +import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest'; |
2 | 2 | import { GET } from './route'; |
3 | 3 | import { createMockSupabaseClient, mockUser, mockSession } from '@/test/mocks/supabase'; |
4 | 4 |
|
5 | 5 | const mockGetAuthenticatedUser = vi.fn(); |
| 6 | +const mockCreateSupabaseClient = vi.fn(); |
6 | 7 |
|
7 | 8 | vi.mock('@/lib/supabase/server', () => ({ |
8 | 9 | createClient: vi.fn(), |
9 | 10 | getAuthenticatedUser: (...args: unknown[]) => mockGetAuthenticatedUser(...args), |
10 | 11 | })); |
11 | 12 |
|
| 13 | +vi.mock('@supabase/supabase-js', () => ({ |
| 14 | + createClient: (...args: unknown[]) => mockCreateSupabaseClient(...args), |
| 15 | +})); |
| 16 | + |
12 | 17 | import { createClient } from '@/lib/supabase/server'; |
13 | 18 |
|
14 | 19 | describe('GET /api/sessions/[sessionId]/signal/stream', () => { |
| 20 | + const originalEnv = { ...process.env }; |
| 21 | + |
15 | 22 | beforeEach(() => { |
16 | 23 | vi.clearAllMocks(); |
17 | 24 | vi.spyOn(console, 'error').mockImplementation(() => {}); |
| 25 | + // Set up env vars for token auth tests |
| 26 | + process.env.NEXT_PUBLIC_SUPABASE_URL = 'https://test.supabase.co'; |
| 27 | + process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY = 'test-anon-key'; |
| 28 | + }); |
| 29 | + |
| 30 | + afterEach(() => { |
| 31 | + process.env = { ...originalEnv }; |
18 | 32 | }); |
19 | 33 |
|
20 | | - const createRequest = (sessionId: string, participantId?: string) => { |
21 | | - const url = participantId |
22 | | - ? `http://localhost/api/sessions/${sessionId}/signal/stream?participantId=${participantId}` |
| 34 | + const createRequest = ( |
| 35 | + sessionId: string, |
| 36 | + options?: { participantId?: string; token?: string } |
| 37 | + ) => { |
| 38 | + const params = new URLSearchParams(); |
| 39 | + if (options?.participantId) params.set('participantId', options.participantId); |
| 40 | + if (options?.token) params.set('token', options.token); |
| 41 | + const queryString = params.toString(); |
| 42 | + const url = queryString |
| 43 | + ? `http://localhost/api/sessions/${sessionId}/signal/stream?${queryString}` |
23 | 44 | : `http://localhost/api/sessions/${sessionId}/signal/stream`; |
24 | 45 | return new Request(url, { |
25 | 46 | method: 'GET', |
@@ -150,9 +171,12 @@ describe('GET /api/sessions/[sessionId]/signal/stream', () => { |
150 | 171 | vi.mocked(createClient).mockResolvedValue(mockSupabase as never); |
151 | 172 | mockGetAuthenticatedUser.mockResolvedValue({ user: null, error: null }); |
152 | 173 |
|
153 | | - const response = await GET(createRequest('test-session-id', 'guest-participant-id'), { |
154 | | - params: Promise.resolve({ sessionId: 'test-session-id' }), |
155 | | - }); |
| 174 | + const response = await GET( |
| 175 | + createRequest('test-session-id', { participantId: 'guest-participant-id' }), |
| 176 | + { |
| 177 | + params: Promise.resolve({ sessionId: 'test-session-id' }), |
| 178 | + } |
| 179 | + ); |
156 | 180 |
|
157 | 181 | expect(response.status).toBe(200); |
158 | 182 | expect(response.headers.get('Content-Type')).toBe('text/event-stream'); |
@@ -234,4 +258,120 @@ describe('GET /api/sessions/[sessionId]/signal/stream', () => { |
234 | 258 | expect.any(Function) |
235 | 259 | ); |
236 | 260 | }); |
| 261 | + |
| 262 | + // Token-based authentication tests (for desktop app) |
| 263 | + describe('token-based authentication', () => { |
| 264 | + it('returns SSE stream for authenticated host via token', async () => { |
| 265 | + const mockChannel = { |
| 266 | + on: vi.fn().mockReturnThis(), |
| 267 | + subscribe: vi.fn().mockReturnThis(), |
| 268 | + track: vi.fn().mockResolvedValue('ok'), |
| 269 | + }; |
| 270 | + |
| 271 | + const mockFrom = vi.fn().mockReturnValue({ |
| 272 | + select: vi.fn().mockReturnThis(), |
| 273 | + eq: vi.fn().mockReturnThis(), |
| 274 | + single: vi.fn().mockResolvedValue({ data: mockSession, error: null }), |
| 275 | + }); |
| 276 | + |
| 277 | + const mockSupabase = createMockSupabaseClient({ |
| 278 | + from: mockFrom, |
| 279 | + channel: vi.fn().mockReturnValue(mockChannel), |
| 280 | + removeChannel: vi.fn().mockResolvedValue('ok'), |
| 281 | + auth: { |
| 282 | + getUser: vi.fn().mockResolvedValue({ data: { user: mockUser }, error: null }), |
| 283 | + }, |
| 284 | + }); |
| 285 | + mockCreateSupabaseClient.mockReturnValue(mockSupabase); |
| 286 | + |
| 287 | + const response = await GET(createRequest('test-session-id', { token: 'valid-token' }), { |
| 288 | + params: Promise.resolve({ sessionId: 'test-session-id' }), |
| 289 | + }); |
| 290 | + |
| 291 | + expect(response.status).toBe(200); |
| 292 | + expect(response.headers.get('Content-Type')).toBe('text/event-stream'); |
| 293 | + // Verify createSupabaseClient was called with token in headers |
| 294 | + expect(mockCreateSupabaseClient).toHaveBeenCalledWith( |
| 295 | + 'https://test.supabase.co', |
| 296 | + 'test-anon-key', |
| 297 | + expect.objectContaining({ |
| 298 | + auth: { persistSession: false, autoRefreshToken: false }, |
| 299 | + global: { headers: { Authorization: 'Bearer valid-token' } }, |
| 300 | + }) |
| 301 | + ); |
| 302 | + }); |
| 303 | + |
| 304 | + it('returns 500 when env vars missing for token auth', async () => { |
| 305 | + delete process.env.NEXT_PUBLIC_SUPABASE_URL; |
| 306 | + |
| 307 | + const response = await GET(createRequest('test-session-id', { token: 'some-token' }), { |
| 308 | + params: Promise.resolve({ sessionId: 'test-session-id' }), |
| 309 | + }); |
| 310 | + const body = await response.json(); |
| 311 | + |
| 312 | + expect(response.status).toBe(500); |
| 313 | + expect(body.error).toBe('Server configuration error'); |
| 314 | + }); |
| 315 | + |
| 316 | + it('returns 401 when token is invalid and no participantId', async () => { |
| 317 | + const otherUserSession = { ...mockSession, host_user_id: 'other-user-id' }; |
| 318 | + const mockFrom = vi.fn().mockReturnValue({ |
| 319 | + select: vi.fn().mockReturnThis(), |
| 320 | + eq: vi.fn().mockReturnThis(), |
| 321 | + single: vi.fn().mockResolvedValue({ data: otherUserSession, error: null }), |
| 322 | + }); |
| 323 | + |
| 324 | + const mockSupabase = createMockSupabaseClient({ |
| 325 | + from: mockFrom, |
| 326 | + auth: { |
| 327 | + getUser: vi |
| 328 | + .fn() |
| 329 | + .mockResolvedValue({ data: { user: null }, error: { message: 'Invalid token' } }), |
| 330 | + }, |
| 331 | + }); |
| 332 | + mockCreateSupabaseClient.mockReturnValue(mockSupabase); |
| 333 | + |
| 334 | + const response = await GET(createRequest('test-session-id', { token: 'invalid-token' }), { |
| 335 | + params: Promise.resolve({ sessionId: 'test-session-id' }), |
| 336 | + }); |
| 337 | + const body = await response.json(); |
| 338 | + |
| 339 | + expect(response.status).toBe(401); |
| 340 | + expect(body.error).toBe('Authentication required'); |
| 341 | + }); |
| 342 | + |
| 343 | + it('allows token auth with participantId as fallback', async () => { |
| 344 | + const otherUserSession = { ...mockSession, host_user_id: 'other-user-id' }; |
| 345 | + const mockChannel = { |
| 346 | + on: vi.fn().mockReturnThis(), |
| 347 | + subscribe: vi.fn().mockReturnThis(), |
| 348 | + track: vi.fn().mockResolvedValue('ok'), |
| 349 | + }; |
| 350 | + |
| 351 | + const mockFrom = vi.fn().mockReturnValue({ |
| 352 | + select: vi.fn().mockReturnThis(), |
| 353 | + eq: vi.fn().mockReturnThis(), |
| 354 | + single: vi.fn().mockResolvedValue({ data: otherUserSession, error: null }), |
| 355 | + }); |
| 356 | + |
| 357 | + const mockSupabase = createMockSupabaseClient({ |
| 358 | + from: mockFrom, |
| 359 | + channel: vi.fn().mockReturnValue(mockChannel), |
| 360 | + removeChannel: vi.fn().mockResolvedValue('ok'), |
| 361 | + auth: { |
| 362 | + getUser: vi.fn().mockResolvedValue({ data: { user: null }, error: null }), |
| 363 | + }, |
| 364 | + }); |
| 365 | + mockCreateSupabaseClient.mockReturnValue(mockSupabase); |
| 366 | + |
| 367 | + // Token is invalid but participantId provided as fallback |
| 368 | + const response = await GET( |
| 369 | + createRequest('test-session-id', { token: 'invalid-token', participantId: 'guest-id' }), |
| 370 | + { params: Promise.resolve({ sessionId: 'test-session-id' }) } |
| 371 | + ); |
| 372 | + |
| 373 | + expect(response.status).toBe(200); |
| 374 | + expect(response.headers.get('Content-Type')).toBe('text/event-stream'); |
| 375 | + }); |
| 376 | + }); |
237 | 377 | }); |
0 commit comments